Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
6e98622
fix(cli): declare the @libpg-query/parser import plpgsql-deparser lea…
spydon Sep 25, 2026
e836519
fix(stack): clean up stacks when Docker is unavailable on start and d…
Prashansa-K Sep 25, 2026
b8026df
fix(stack): require passwords on the native database socket (CLI-2503…
7ttp Sep 25, 2026
643d648
fix(stack): start auth with zero session limits (CLI-2506) (#6848)
7ttp Sep 27, 2026
e29a712
fix(stack): upgrade edge-runtime to v1.77.1 (#6844)
jgoux Sep 28, 2026
f5c0a5d
chore(api): sync Management API OpenAPI spec (#6826)
supabase-cli-releaser[bot] Sep 28, 2026
f70cda5
fix(cli): read request bodies before local functions respond (#6830)
jgoux Sep 28, 2026
e03ea7c
fix(stack): stop Postgres containers with a fast shutdown (#6834)
jgoux Sep 28, 2026
257bee9
perf(cli): initialize catalog schemas without temporary servers (#6831)
jgoux Sep 28, 2026
2c006dd
fix(stack): harden readiness, port claims, and container storage (#6835)
jgoux Sep 28, 2026
d4826ec
refactor(stack): flatten the owner process layers (#6836)
jgoux Sep 28, 2026
97c71e7
refactor(stack): unify the database snapshot protocol across engines …
jgoux Sep 28, 2026
d021886
feat(cli): drive gen types languages from the @supabase/typegen regis…
spydon Sep 28, 2026
dfc52e6
feat(stack): lease owners with a lock and bind session stacks to crea…
jgoux Sep 28, 2026
7cd1a79
feat(stack): ship the functions bootstrap with the package (#6839)
jgoux Sep 28, 2026
1ef5bc0
fix(cli): prefer Docker, then Podman, for automatic stack runtime sel…
jgoux Sep 28, 2026
8e48a07
refactor(stack): own composition policy and stack lookup in the packa…
jgoux Sep 28, 2026
afe855a
ci(release): upload release assets one at a time with retries (CLI-24…
kanadgupta Sep 28, 2026
b55d919
refactor(cli): cover all `commands` with effect lint (CLI-2408) (#6849)
7ttp Sep 28, 2026
a883019
fix(stack): connect Studio to the database and restore its settings (…
avallete Sep 29, 2026
315dbcd
fix(stack): name containers by project and service (#6867)
avallete Sep 29, 2026
7894283
feat(stack): add a testing entrypoint and derive the Promise API (#6841)
jgoux Sep 29, 2026
2547ce5
fix(stack): group database helper containers with their stack (#6870)
avallete Sep 29, 2026
66e92c7
fix(stack): keep Studio awake for 5 minutes after its last request (#…
avallete Sep 29, 2026
ff14e91
fix(stack): reduce native stack friction in agent sandboxes (#6856)
avallete Sep 29, 2026
04b1ce9
fix(cli): label non-stable builds in the root help description (#6868)
kanadgupta Sep 29, 2026
8bc13e0
test(stack): wait for the detached owner to exit before removing its …
jgoux Sep 29, 2026
6ea2248
chore: bump pnpm/bun/node, various cleanups (#6806)
kanadgupta Sep 29, 2026
ed05cb8
fix(stack): retry image pulls after transient registry failures (#6879)
jgoux Sep 29, 2026
2124262
test(cli): connect live db assertions over TLS (#6843)
avallete Sep 29, 2026
5abfa7d
ci(cli): cache pnpm lockfile verification and drop the Linux stack-po…
kanadgupta Sep 29, 2026
c7c9f12
refactor(cli): cover `shared/telemetry` identity and consent with eff…
7ttp Sep 29, 2026
9001c3a
refactor(cli): cover `shared/telemetry` posthog transport with effect…
7ttp Sep 29, 2026
7fa68d3
refactor(cli): cover `shared/telemetry` tests with effect lint (CLI-2…
7ttp Sep 29, 2026
7ececb6
refactor(cli): cover `shared/config` and `shared/auth` with effect li…
7ttp Sep 29, 2026
98cda96
fix(stack): keep in-progress artifact extractions safe from the lefto…
jgoux Sep 29, 2026
d38ccd7
test(repo): replace real-time waits in slow CLI and stack tests (#6862)
jgoux Sep 29, 2026
621768f
fix(stack): release log followers on exit (CLI-2521) (#6861)
7ttp Sep 29, 2026
f6d5078
refactor(cli): cover `shared/runtime` with effect lint (CLI-2519) (#6…
7ttp Sep 29, 2026
e49b791
fix(stack): keep in-use cached artifacts when a request needs more pa…
jgoux Sep 29, 2026
72b10f8
fix(cli): keep migra session settings on reconnect (CLI-2522) (#6884)
7ttp Sep 29, 2026
2a66b74
ci(repo): rebalance slow test jobs and raise integration workers (#6863)
jgoux Sep 29, 2026
288edc2
fix(cli): show stack connection details on start and status (CLI-2546…
avallete Sep 30, 2026
80dc4e0
ci(repo): move the AI review pipeline to gpt-6.1-sol (#6899)
Coly010 Sep 30, 2026
5800d06
test(repo): fix windows and live e2e flakes (#6895)
7ttp Sep 30, 2026
a1be13e
fix(stack): open a fresh upstream connection per proxied request (#6897)
jgoux Sep 30, 2026
b56c765
refactor(cli): cover `shared/git` and `shared/issue` with effect lint…
7ttp Sep 30, 2026
63a2ff5
fix(cli): state stack destroy --yes instead of self-answering prompt …
avallete Sep 30, 2026
6ef3315
test(cli): make reset and stack start integration tests pass on Windo…
avallete Sep 30, 2026
2d7609d
fix(cli): treat the stack database --db-url as local (#6904)
avallete Sep 30, 2026
4371ed3
fix(stack): load function deno.json files as Deno config (#6907)
avallete Sep 30, 2026
b8fae81
fix(cli): tidy stack start and non-TTY output friction (#6889)
avallete Sep 30, 2026
87d9efb
fix(stack): reach stack services from Windows and Docker Desktop cont…
avallete Sep 30, 2026
48cabe3
feat(cli): graduate OrioleDB configuration from experimental (#6828)
jgoux Sep 30, 2026
8ae22bc
feat(stack): serve Studio's MCP server at /mcp on the API listener (C…
jgoux Sep 30, 2026
8a7963e
feat(cli): upgrade pg-delta to 1.0.0-alpha.56 (#6913)
avallete Sep 30, 2026
2799c9f
refactor(cli): cover `/shared` init, feedback and services with effec…
7ttp Sep 30, 2026
eb0c3ff
fix(config): ignore unset sms provider (CLI-2463) (#6685)
7ttp Sep 30, 2026
233d145
fix(cli): stop splitting escape strings on escaped quotes (CLI-2537) …
7ttp Sep 30, 2026
b202ba6
refactor(cli): cover `shared/output` with effect lint (CLI-2561) (#6912)
7ttp Sep 30, 2026
26dc09a
feat(cli): report stack MCP at the API URL and include connection env…
jgoux Sep 30, 2026
b29e743
fix(cli): decline unrecognised yes/no prompt answers (CLI-2524) (#6910)
7ttp Sep 30, 2026
c877778
fix(cli): reject `test new` names that escape supabase/tests (CLI-248…
7ttp Sep 30, 2026
2b13026
fix(stack): give each Mailpit instance its own database (#6901)
jgoux Sep 30, 2026
bb809cf
chore(stack): log lazy wakes instead of bounding them in the proxy (#…
jgoux Sep 30, 2026
3704383
fix(cli): skip the contrib_regression clone on pg-delta shadows (#6920)
avallete Sep 30, 2026
a0711c0
fix(stack): keep Storage uploads working on Docker Desktop for macOS …
avallete Sep 30, 2026
481cb3f
fix(stack): serve Storage S3 and resumable uploads behind the gateway…
avallete Sep 30, 2026
62aac0f
feat(stack): pin slim artifacts by revision and make the catalog the …
jgoux Sep 30, 2026
985e0ae
fix(stack): reuse keep-alive upstream connections in the HTTP gateway…
avallete Sep 30, 2026
3cb948c
chore(api): sync Management API OpenAPI spec (#6880)
supabase-cli-releaser[bot] Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .bun-version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.4.1
1.4.2
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ apps/cli-go/api/v1-openapi.yaml linguist-generated=true
apps/cli-go/pkg/api/*.gen.go linguist-generated=true
packages/api/src/generated/* linguist-generated=true
packages/api/scripts/openapi-source.json linguist-generated=true
packages/stack/src/functions/generated/* text eol=lf linguist-generated=true
apps/cli/src/shared/feedback/database.types.ts linguist-generated=true
apps/docs/public/cli/config.schema.json linguist-generated=true
apps/docs/public/cli/project-config.schema.json linguist-generated=true
Expand Down
27 changes: 25 additions & 2 deletions .github/actions/setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,12 @@ inputs:
fails with a path validation error.
required: false
default: "true"
go-cache:
description: >-
Whether to restore the Go module and build caches. Disable this in jobs
that never run Go.
required: false
default: "true"

runs:
using: "composite"
Expand Down Expand Up @@ -52,16 +58,33 @@ runs:
restore-keys: |
pnpm-store-files-${{ runner.os }}-${{ runner.arch }}-

- name: Resolve Go cache paths
- name: Resolve pnpm cache path
if: inputs.dependency-cache == 'true'
id: pnpm-cache
shell: bash
run: echo "path=$(pnpm cache path --silent)" >> "$GITHUB_OUTPUT"

# pnpm stores the lockfile's supply-chain verdict in lockfile-verified.jsonl;
# without it every job re-verifies all entries against registry metadata,
# which dominates a warm-store install. The verdict is bound to the policy
# and to the registry it was checked against.
- name: Configure pnpm verification cache
if: inputs.dependency-cache == 'true'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ steps.pnpm-cache.outputs.path }}/lockfile-verified.jsonl
key: pnpm-verify-${{ runner.os }}-${{ inputs.dependency-firewall-token != '' && 'firewall' || 'public' }}-${{ hashFiles('pnpm-lock.yaml', 'pnpm-workspace.yaml') }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Severity: MEDIUM

The verification cache key contains no dependency-firewall policy or registry revision and has no expiry. A prior positive lockfile-verified.jsonl can therefore be reused after a dependency is newly blocked or its registry verdict changes, allowing it to pass the install gate in CI and release builds.
Helpful? Add 👍 / 👎

💡 Fix Suggestion

Suggestion: The verification cache key must be made invalidatable when firewall policy or registry verdicts change, independent of lockfile content. Two complementary approaches are recommended:

  1. Add a verify-cache-version input (recommended): In the inputs: section of action.yml, add a new input such as verify-cache-version with a default of "1" and a description explaining it should be bumped when the Dependency Firewall policy changes. Then incorporate it into the cache key at line 76, e.g.: key: pnpm-verify-v${{ inputs.verify-cache-version }}-${{ runner.os }}-${{ inputs.dependency-firewall-token != '' && 'firewall' || 'public' }}-${{ hashFiles('pnpm-lock.yaml', 'pnpm-workspace.yaml') }}. Callers bump the version via workflow dispatch or config change whenever a new firewall policy is deployed.

  2. Add a weekly date component: Insert a step before the 'Configure pnpm verification cache' step that emits the current ISO year+week number (e.g., echo "week=$(date -u +%Y%W)" >> "$GITHUB_OUTPUT") and reference it in the key: ...-${{ steps.week.outputs.week }}-${{ hashFiles(...) }}. This guarantees verdicts are re-queried at least once a week even if lockfiles do not change, bounding the window during which a newly-blocked or re-scored dependency can slip through on a stale cached verdict.

Both changes require modifying a location other than line 76: Option 1 requires adding a new entry in the inputs: block (lines 5–21) and then referencing it in the key; Option 2 requires inserting a new shell step before line 74.


- name: Resolve Go cache paths
if: inputs.dependency-cache == 'true' && inputs.go-cache == 'true'
id: go-cache
shell: bash
run: |
echo "mod=$(go env GOMODCACHE)" >> "$GITHUB_OUTPUT"
echo "build=$(go env GOCACHE)" >> "$GITHUB_OUTPUT"

- name: Configure Go dependency cache
if: inputs.dependency-cache == 'true'
if: inputs.dependency-cache == 'true' && inputs.go-cache == 'true'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
Expand Down
15 changes: 15 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -85,11 +85,26 @@ updates:
update-types:
- minor
- patch
# These lines are generated from packages/stack/src/Artifacts.ts (the single version table
# for slim-capable services); updates to them arrive through slim-release-published.yml, not
# Dependabot. Kong and pg14 (supabase/postgres) have no slim build either, but are bumped by
# hand, not by Dependabot. Dependabot keeps bumping only the images that remain genuinely
# upstream-only: migra, pg_prove, pgadmin-schema-diff.
ignore:
- dependency-name: "library/kong"
- dependency-name: "axllent/mailpit"
- dependency-name: "darthsim/imgproxy"
- dependency-name: "timberio/vector"
- dependency-name: "supabase/postgres"
- dependency-name: "supabase/gotrue"
- dependency-name: "postgrest/postgrest"
- dependency-name: "supabase/realtime"
- dependency-name: "supabase/storage-api"
- dependency-name: "supabase/edge-runtime"
- dependency-name: "supabase/studio"
- dependency-name: "supabase/postgres-meta"
- dependency-name: "supabase/logflare"
- dependency-name: "supabase/supavisor"
cooldown:
default-days: 7
exclude:
Expand Down
2 changes: 1 addition & 1 deletion .github/scripts/slim-mirror-payload.ts
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
*/

const SERVICE_PATTERN = /^[a-z][a-z0-9-]*$/;
export const VERSION_PATTERN = /^[A-Za-z0-9._-]+$/;
const VERSION_PATTERN = /^[A-Za-z0-9._-]+$/;
export const DIGEST_PATTERN = /^sha256:[0-9a-f]{64}$/;

export const SOURCE_REGISTRY = "ghcr.io/supabase/cli";
Expand Down
Loading
Loading